PT-2022-23784 · H3C · H3C Gr-1200W

Published

2022-08-25

·

Updated

2023-08-08

·

CVE-2022-37070

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions H3C GR-1200W version MiniGRW1A0V100R006
Description A command injection issue was discovered via the param parameter at DelL2tpLNSList.
Recommendations For H3C GR-1200W version MiniGRW1A0V100R006, consider restricting access to the DelL2tpLNSList endpoint to minimize the risk of exploitation. Avoid using the param parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-37070

Affected Products

H3C Gr-1200W